Owner Control of Electronic Devices via Digital Signatures
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In corporate environments, employees using electronic devices often circumvent control measures by deleting or altering policy files, leading to a lack of effective owner control over device usage, as existing methods rely on user compliance with company policies and are vulnerable to circumvention.
Innovation Solution
A system and method for owner control of electronic devices, involving an owner information store for data integrity and source authentication, and an owner control information store to restrict operations, with digitally signed erase commands ensuring secure management of owner information and control settings.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If policy files are loaded onto devices to restrict operations, then owner control over device usage is improved, but users can circumvent control by deleting or replacing policy files
Solution Approach 1:
The system separates policy management into two distinct components: policy files that define restrictions and digitally signed commands that authorize changes. This segmentation ensures that users cannot simply delete or replace policy files, as any modification requires a valid digitally signed command from an authorized source, thus maintaining owner control while allowing legitimate user operations.
Solution Approach 2:
The system pre-loads policy files onto devices during initial setup or provisioning, before users can potentially circumvent them. These policy files are established in advance with digital signatures that verify their authenticity. Any subsequent changes to policies or device settings require pre-authenticated digitally signed commands, preventing users from arbitrarily modifying restrictions after receiving the device.
2Ease of operation
If users are allowed to make changes to device settings, then ease of operation is improved, but owner control and policy compliance deteriorate
Solution Approach 1:
The system introduces digitally signed commands as an intermediary mechanism between user requests and device setting changes. When a user attempts to modify device settings, the system checks for a valid digitally signed command that authorizes the specific change. This intermediary layer allows legitimate user operations to proceed while blocking unauthorized modifications, thus maintaining both ease of operation for authorized users and policy compliance.
Solution Approach 2:
The system implements a feedback mechanism where any attempt to modify device settings triggers a verification process. The system checks whether a valid digitally signed command exists for the requested change and provides feedback by either allowing or blocking the modification. This feedback loop ensures that users can make necessary changes when authorized while automatically preventing policy violations, maintaining both usability and compliance.
Data Source
AI summary
A system and method of owner control of an electronic device are provided. Owner identification information, such as data integrity and source authentication information, is stored on the electronic device. Received owner control information is stored on the electronic device where the integrity of the received owner control information is verified and/or the source is authenticated using the owner identification information. In one embodiment, owner identification information comprises an owner signature private key.


